BdThemes' compromised JSON feed exploits XSS in seven WordPress plugins, creating rogue admins and installing a PHP web shell without plugin updates.
BdThemes supply chain attack poisons JSON feed to create rogue WordPress admins and deploy web shells without code changes.
Wordfence was notified of the compromise on August 7 and published its analysis the following day. It affects BdThemes, an Elementor add-on vendor whose plugins are distributed through the official ...
Pakistan’s National CERT has warned of critical WordPress flaws that could let hackers take control of websites and urged organizations to patch them immediately.
Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch ...
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected ...
Security researchers have discovered two vulnerabilities in WordPress that can be chained into an exploit, enabling the injection of malicious code. Administrators of the popular blog system should ...
Stop uploading to Google Drive for file sharing—this app keeps everything on your Wi-Fi.
President Trump revealed that China stole the voter registration data of 220 million Americans as part of his primetime speech on Thursday. “Over a period of years, starting during the 2020 election ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results